Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2748▲ 37 respecto a la semana anterior
Críticas / altas1479▲ 369 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

35 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.24%—Parla Auto Automotive Trading Limited Company Detawix Mobile WEB PortalAI29/9/202630/9/2026
Insertion of sensitive information into sent data vulnerability in Parla Auto Automotive Trading Limited Company DetaWix Mobile Web Portal allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects DetaWix Mobile Web Portal: before v1.0.19.
Pendiente de análisisMedia (5.6)0.25%—Checkpoint DLPAICheckpoint Usercheck WEB PortalAI26/5/202624/7/2026
When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow. Under specific conditions, an attacker who can access the UserCheck Ask page could attempt to manipulate the Security Gateway's stored DLP/UserCheck incident information. This could lead to disruptions such as…
AnalizadaBaja (2.1)0.47%—Carmelo Student WEB Portal8/3/202617/6/2026
A vulnerability was found in code-projects Student Web Portal 1.0. Affected is an unknown function of the file profile.php. The manipulation of the argument User results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.
AnalizadaMedia (5.5)0.58%—Carmelo Student WEB Portal8/3/202617/6/2026
A vulnerability has been found in code-projects Student Web Portal 1.0. This impacts the function valreg_passwdation of the file signup.php. The manipulation of the argument reg_passwd leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
AnalizadaMedia (6.9)0.39%—Carmelo Student WEB Portal8/2/202617/6/2026
A vulnerability was detected in code-projects Student Web Portal 1.0. This impacts an unknown function of the file /check_user.php. Performing a manipulation of the argument Username results in sql injection. It is possible to initiate the attack remotely.
AplazadaAlta (8.6)0.45%—Saysis Computer Systems Trade LTD CO Saysis WEB PortalAI25/9/202517/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Saysis Computer Systems Trade Ltd. Co. Saysis Web Portal allows Path Traversal. This issue affects Saysis Web Portal: from 3.1.9 & 3.2.0 before 3.2.1.
AplazadaCrítica (9.3)0.29%—Pixmeo Osirix MD WEB PortalAI8/5/202517/6/2026
The Pixmeo Osirix MD Web Portal sends credential information without encryption, which could allow an attacker to steal credentials.
AplazadaAlta (7.5)0.40%—Priority WEB Portal Add-onAI30/7/202417/6/2026
Priority PRI WEB Portal Add-On for Priority ERP on prem - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
ModificadaMedia (5.4)0.76%—Webport WEB Port24/6/202117/6/2026
Cross Site Scripting (XSS) vulnerabililty in WebPort <=1.19.1 via the description parameter to script/listcalls.
ModificadaMedia (5.3)1.7%—Webport WEB Port24/6/202117/6/2026
Directory Traversal vulnerability in WebPort <=1.19.1 in tags of system settings.
ModificadaMedia (5.4)0.73%—Webport WEB Port24/6/202117/6/2026
Cross Site Scripting (XSS) vulnerability in WebPort <=1.19.1via the connection name parameter in type-conn.
ModificadaMedia (5.4)0.56%—Webport WEB Port26/8/202017/6/2026
WebPort-v1.19.17121 is affected by Cross Site Scripting (XSS) on the "connections" feature.
ModificadaMedia (6.1)9.9%—Webport WEB Port30/5/201917/6/2026
Web Port 1.19.1 allows XSS via the /log type parameter.
ModificadaMedia (6.1)3.8%—Webport WEB Port30/5/201917/6/2026
Web Port 1.19.1 allows XSS via the /access/setup type parameter.
ModificadaAlta (7.5)5.3%—CA Erwin WEB Portal4/4/201417/6/2026
Multiple directory traversal vulnerabilities in CA ERwin Web Portal 9.5 allow remote attackers to obtain sensitive information, bypass intended access restrictions, cause a denial of service, or possibly execute arbitrary code via unspecified vectors.
ModificadaMedia (4.3)1.6%—Simhl Sths V2 WEB Portal21/2/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in STHS v2 Web Portal 2.2 allow remote attackers to inject arbitrary web script or HTML via the team parameter to (1) prospects.php, (2) prospect.php, or (3) team.php.
ModificadaMedia (5)1.6%—Comscripts WEB Server Creator WEB Portal25/3/201016/6/2026
Directory traversal vulnerability in news/include/customize.php in Web Server Creator - Web Portal 0.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the l parameter.
ModificadaAlta (7.5)3.0%—Comscripts WEB Server Creator WEB Portal25/3/201016/6/2026
Multiple PHP remote file inclusion vulnerabilities in Web Server Creator - Web Portal 0.1 allow remote attackers to execute arbitrary PHP code via a URL in the (1) pg parameter to index.php and the (2) path parameter to news/form.php.
ModificadaMedia (4.3)1.4%—Comscripts WEB Server Creator WEB Portal25/3/201016/6/2026
Cross-site scripting (XSS) vulnerability in the forum page in Web Server Creator - Web Portal 0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors to index.php.
ModificadaAlta (7.5)2.3%—Comscripts WEB Server Creator WEB Portal30/3/200916/6/2026
PHP remote file inclusion vulnerability in news/include/createdb.php in Web Server Creator Web Portal 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the langfile parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (10)4.0%—Sportspanel Sports Clubs WEB Portal16/10/200816/6/2026
Directory traversal vulnerability in index.php in Sports Clubs Web Panel 0.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the p parameter.
ModificadaAlta (7.5)1.0%—Aspindir Munzursoft WEB Portal W315/10/200816/6/2026
SQL injection vulnerability in kategori.asp in MunzurSoft Wep Portal W3 allows remote attackers to execute arbitrary SQL commands via the kat parameter.
ModificadaAlta (7.5)1.3%—Jportal WEB Portal15/11/200716/6/2026
SQL injection vulnerability in mailer.php in JPortal 2 allows remote attackers to execute arbitrary SQL commands via the to parameter.
ModificadaAlta (7.5)0.99%—Jportal WEB Portal15/11/200716/6/2026
SQL injection vulnerability in articles.php in JPortal 2.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter.
ModificadaAlta (7.5)0.97%—Jportal WEB Portal10/11/200716/6/2026
SQL injection vulnerability in mailer.php in jPORTAL 2 allows remote attackers to execute arbitrary SQL commands via the to parameter.